MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 bdfc5b93705161e526cd29e186ea5f3e0211bfa5fbdc46b7a5867397bc4f6c3c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 2
| SHA256 hash: | bdfc5b93705161e526cd29e186ea5f3e0211bfa5fbdc46b7a5867397bc4f6c3c |
|---|---|
| SHA3-384 hash: | d19d666eddf27762e82ff8c4257319f8ab09dffdee6c93e41a016f563335365c5955cdaab8ca5f24849cd112e3fdcc0a |
| SHA1 hash: | f95358c87e6c629dbf6846ceec25afe69bfc0666 |
| MD5 hash: | 4845ad963a0f6fca2ada9a966eedd2ea |
| humanhash: | connecticut-cup-three-indigo |
| File name: | OILMARKTL QUOTATION.zip |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 604'876 bytes |
| First seen: | 2020-08-31 09:24:41 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:bPg1JI01mvMmd8HVQI8C+pVYkDzDIFmJ8o0twGbedTQeYEumrK:0nVaMVHVQI8hpADoKxedTQeYEuEK |
| TLSH | 99D42315334EBE9445634CEB08D6E865C8BE803D2BA0BADD4AB473D990E319771B1DB3 |
| Reporter | |
| Tags: | AgentTesla zip |
abuse_ch
Malspam distributing AgentTesla:HELO: gains.hificlouds.com
Sending IP: 131.153.48.114
From: ME <sales@oilmarkntl.com>
Subject: RE:OILMARK - INSTRUMENTATION-ELECTRICAL-SAFETY-AUTOMATION SUPPLIER **(QUOTATION)**
Attachment: OILMARKTL QUOTATION.zip (contains "OILMARKTL QUOTATION.exe")
AgentTesla SMTP exfil server:
smtp.ritac-eg.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.45
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.